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As Russia, China, and other states advance influence through forms of digital authoritarianism, stronger 
responses are needed from the U.S. and like-minded partners to limit the effects of their efforts. 


EXECUTIVE SUMMARY 


Digital authoritarianism — the use of digital 
information technology by authoritarian regimes 
to surveil, repress, and manipulate domestic 
and foreign populations — is reshaping the power 
balance between democracies and autocracies. 
At the forefront of this phenomenon, China and 
Russia have developed and exported distinct 
technology-driven playbooks for authoritarian rule. 
Beijing’s experience using digital tools for domestic 
censorship and surveillance has made it the supplier 
of choice for illiberal regimes looking to deploy 
their own surveillance systems, while Moscow’s 
lower-cost digital disinformation tools have proven 
effective in repressing potential opposition at home 
and undermining democracies abroad. 


This policy brief examines the development and 
export of both the Chinese and Russian models. 
China pioneered digital age censorship with its 
“Great Firewall” of a state-controlled Internet and 


unprecedented high-tech repression deployed 
in Xinjiang in recent years, and has exported 
surveillance and monitoring systems to at least 18 
countries. Russia relies less on filtering information 
and more on a repressive legal regime and 
intimidation of key companies and civil society, a 
lower-cost ad hoc model more easily transferable to 
most countries. The Russian government has made 
recent legal and technical moves which further 
tighten control, including legislation passed this 
year to establish a “sovereign Russian internet.” 


The authors recommend that the United States 
and other democracies should tighten export 
controls on technologies that advance digital 
authoritarianism, sanction regimes engaging in 
digital authoritarianism and firms that supply them, 
develop a competitive democratic model of digital 
governance with a code of conduct, and increase 
public awareness around information manipulation, 
including funding educational programs to build 
digital critical thinking skills among youth. 
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INTRODUCTION 


In January 2010, Secretary of State Hillary Clinton 
delivered a landmark speech on internet freedom in 
whichsheargued thatthespread of communications 
technology and free flow of information would 
ultimately lead to greater freedom and democracy. 
In the years since, that view has come under 
increasing strain. Most notably, China and Russia 
have learned how to leverage both the internet and 
information technology in ways that have reduced 
rather than expanded human freedom. Worse, 
they have also begun to export their models of 
digital authoritarianism across the globe. Absent 
an effective democratic response, including an 
international rules of the road framework around 
surveillence technology exports, further advances 
in information technology may well yield a world of 
ever greater repression rather than liberalization. 


Digital authoritarianism — the use of digital 
information technology by authoritarian regimes 
to surveil, repress, and manipulate domestic and 
foreign populations — is reshaping the power 
balance between democracies and autocracies. 
While China is driving innovation in high-tech 
social control, Russia has been more willing to 
weaponize information technologies as part of 
targeted influence operations. Both countries have 
developed and exported new tech-driven playbooks 
for authoritarian rule, but their strategies are quite 
distinct. The Chinese have long pioneered digital 
tools for domestic censorship and surveillance, 
dating back to the initial launch of its “Great Firewall” 
over two decades ago. More recently, Beijing’s long 
experience building a robust digital surveillance 
architecture has started to pay dividends: China 
has increasingly become the supplier of choice 
for illiberal regimes looking to deploy surveillance 
systems of their own. 


By contrast, Moscow is struggling to catch up 
with China’s high-tech model of domestic control. 
Although the Russian government has sought to 
clamp down on internet freedom, gain access to 
citizens’ personal data, and impose more control 


on the digital domain since the early 2000s, it 
has not been the “industry leader” in developing 
these tools. Rather, Moscow’s domestic model 
is relatively low-tech when it comes to domestic 
surveillance. Its main focus has been the export of 
digital disinformation tools — a suite of information 
influence techniques easily bought and deployed by 
other state and non-state actors. Moscow’s model 
of low-tech surveillance, due to its relative low cost 
and adaptability, is finding appeal among resource- 
poor governments that lack China’s economic 
prowess, human capital capacities, and centralized 
state control. 


Yet as different as the Chinese and Russian 
motivations and capabilities have been, the 
end result is remarkably similar: each country 
has developed a set of tools that enable rising 
authoritarians to repress potential opposition at 
home while undermining democracies abroad. 


THE CHINESE MODEL 


Beijing’s approach to information technology dates 
back to the reformist era of Deng Xiaoping. In keeping 
with Deng’s vision for opening China’s economy 
while maintaining social stability, Zhongnanhai 
has consistently viewed digital technology as a key 
driver of economic development as well as a tool 
for preserving and even extending political control.? 
The strategy has largely been a success. China 
now boasts world-class technology and the second 
largest economy in the world,? yet the country’s 
openness to global trade and information technology 
has not led to any meaningful political reform. The 
Chinese Communist Party (CCP) remains thoroughly 
entrenched in power, and Xi Jinping enjoys an 
extraordinary degree of political control.4 


Beijing has leveraged information technology both 
online and offline. Email first arrived in China in 
1987, and the commercial internet in 1994.° Not 
long after, Party leaders began insisting that the 
web would need to be used in accord with “Chinese 
characteristics.”© In 1996, when only 150,000 
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Chinese were online, State Council Order No. 195 
explicitly brought the internet under state control. 
Within a year Wired was already referring to the 
“The Great Firewall of China.”” In the twenty years 
since, Beijing’s legal and technical architecture 
for web censorship and surveillance has grown 
dramatically. Although Xi centralized control over 
the internet in 2013, principally through the creation 
of a Cyberspace Administration that reports directly 
to him, the Chinese web is now overseen by over 
sixty agencies with vast legal and technical ability to 
monitor and regulate online activity.® 


Far from sparking a political opening, within 
China the internet has been a valuable space 
for state censorship and surveillance. 


Beijing’s control over both the infrastructure and 
application layer of the web has had a profound 
impact on political behavior.? Althoughthe CCP allows 
for some forms of criticism,*° dissidents and human 
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Imams and Chinese government officials pass under security cameras as they leave the Id Kah Mosque in Kashgar, Xinjiang Uighur 
Autonomous Region, China, during a trip organized by the government for foreign reporters. January 4, 2019. REUTERS/Ben Blanchard 


rights activists are nonetheless frequently detained 
for what they post on popular social media sites like 
Weibo and WeChat, both of which are aggressively 
monitored.** (Indeed, in Xinjiang, residents are only 
allowed to use WeChat, precisely because it is so 
widely monitored.)*? Meanwhile, applications and 
websites that do not comply with Beijing’s demands 
operate at considerable peril: in the first three weeks 
of 2019 alone, the Xi regime shut down over 700 
websites and 9,000 mobile apps, including those 
owned by prominent companies like Tencent.*® 
Far from sparking a political opening, within China 
the internet has been a valuable space for state 
censorship and surveillance. 


Yet the Chinese are not just monitoring online 
activity. In 2005, the Ministry of Public Security 
(MPS) and Ministry of Industry and Information 
Technology (MIIT) jointly launched a program called 
SkyNet, which aimed to install a national network of 
CCTV feeds.* By 2010, Beijing alone was blanketed 
with 800,000 surveillance cameras, and by 2015 
Beijing police boasted that the city was 100% 
covered. More than 20 million more cameras were 
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in use nationwide.** Based on the success of the 
SkyNet program, the National Development and 
Reform Commission (NDRC) in 2015 then set the 
ambitious goal of covering all of China’s public 
spaces and leading industries in cameras by 2020, 
with the aim of creating an “omnipresent, fully 
networked, always working and fully controllable” 
surveillance system.7® Although that goal is far- 
fetched, the resulting “Sharp Eyes” initiative is 
nonetheless extraordinary for its reach and scope. 
The project, whose title alludes to the CCP slogan 
“the people have sharp eyes,”*’ promises to link 
together smartphones and smart TVs as well as 
surveillance cameras, and has already produced 
smartphone apps individuals can use to monitor 
feeds and report suspicious activities.** As “Sharp 
Eyes” feeds are coupled with location data taken 
from smartphones and vehicles, Beijing will 
increasingly be able to monitor the movements and 
behavior of its citizens in unprecedented detail.*° 


However, China’s vision for a real-time, nationwide 
surveillance network will require more than just 
ubiquitous video streams and sensor data. It will also 
need to leverage artificial intelligence (Al) to identify 
and track individuals across the network. As a result, 
Chinese companies like HikVision, the world’s 
largest manufacturer of surveillance equipment, 
have moved aggressively to meet that demand,”° 
while Beijing has invested heavily in domestic Al 
startups like Sensetime, Yitu, and Megvii, which 
received over $2 billion in government initiated 
investment in 2018.74 SenseTime alone has the goal 
of creating a system that can monitor 100,000 high- 
resolution video feeds simultaneously and identify 
and track individuals across them in real-time.?? 
Early efforts at such a network have illustrated its 
promise for local policing: during a concert in Jiangxi 
province in May 2018, a facial recognition software 
alerted concert security that one of the 60,000 
concert goers was actually a suspected fugitive. 
The 31-year-old man was arrested within minutes,?? 
and now represents one of thousands that state 
authorities claim SkyNet and similar programs have 
helped capture.” 


Beijing is not just constructing separate 
surveillance systems for the web and real-world. It 
is also increasingly seeking to link the two. Most 
notably, in 2014 the State Council announced its 
goal to establish a national “social credit score” 
system by 2020.75 As with “Sharp Eyes,” that 
deadline will likely prove infeasible. A national 
system that can aggregate bank data, hospital 
records, real-world movements, online activity, and 
other records into a single “trustworthiness” score 
is still more an aspiration than a reality, as Jamie 
Horsely and others have noted. But in mandating 
a system that will “allow the trustworthy to roam 
everywhere under heaven while making it hard for 
the discredited to take a single step,” the State 
Council has nonetheless incentivized the creation 
of a Suite of digital tools for algorithmic governance 
without meaningful due process.?’ By transforming 
online and offline data into a single measure that 
is then coupled with state power, the early social 
credit systems that have emerged promise to 
serve as a lever of social control that 20th century 
authoritarian regimes could only dream of. 


China’s development of “the autocrat’s new toolkit,” 
as Richard Fontaine and Kara Frederick have put 
it, will have a profound impact on the rights and 
liberties of all its citizens.2° Yet that impact has 
already been felt far more acutely by one group in 
particular. 


Xinjiang and the Strike Hard Campaign 


Beijing has pioneered many of its most repressive 
surveillance technologies in the Muslim and 
Turkic-speaking provinces of western China.”° In 
2009, after two Uighurs were injured in fights with 
ethnically Han workers at a factory, rioting broke out 
in Urumqi, the capital of Xinjiang.°° The resulting 
violence left more than 150 dead, and represented 
the worst unrest in China since the Tiananmen 
crackdown twenty years’ earlier.** Beijing’s 
crackdown in response only sparked further, more 
deliberate violence: in 2013, militants from Xinjiang 
carried out a vehicle attack in Tiananmen square, 
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killing five;S? in May 2014, five suicide bombers in 
Urumdi killed over 30 civilians;°? in June 2014, at 
Kunming Station in Yunnan province, eight knife- 
wielding attackers from Xinjiang killed 29 more.** 


As the violence escalated, Beijing grew impatient. 
In May 2014, China’s national police ministry 
implemented a new “Strike Hard Campaign against 
Violent Terrorism.”°° As with prior “Strike Hard” 
campaigns in the region, the new campaign made 
extensive use of mass arrests and pre-trial detention 
centers. By the end of 2014, arrests in Xinjiang had 
doubled from the year before,°° a figure that would 
soon rise three-fold.°’ Arrests and detentions have 
risen so dramatically in Xinjiang that up to 1 million 
individuals are now being held in various camps, 
centers, and prisons across Xinjiang.*° 


Yet the Strike Hard Campaign is unprecedented not 
just for its sheer scale, but also for its novel use and 
deployment of technology. Although authorities in 
Xinjiang have long used information technology to 
counter unrest —to quell the 2009 riots, for example, 
they shut down all internet and text-messaging 
in the region®? — they had never previously used 
it with such precision and ubiquity. In August 
2016, after Chen Quanguo was appointed Party 
Secretary in Xinjiang, he brought with him many 
of the securitization measures and surveillance 
technologies he introduced in Tibet.*° By greatly 
expanding the number of police checkpoints in 
Xinjiang and outfitting them with biometric sensors, 
iris scanners, and access to nearby CCTV cameras, 
Chinese security services in Xinjiang have been 
able to monitor the movement and behavior of its 
residents in unparalleled detail, with Uighurs in 
particular being singled out. At police checkpoints, 
Uighurs frequently have their DNA collected and 
their eyes scanned,** and they may be forced to 
install spyware on their phones that tracks all of 
their online activity.** To cover Uighur movement 
between checkpoints, the CCP has also mandated 
all vehicles in Xinjiang to install a navigation system 
powered by Beidou, China’s version of the Global 
Position System, or GPS.*? In addition, security 


services in Xinjiang have also begun to deploy 
flocks of small bird-like surveillance drones to cover 
areas that CCTV feeds do not track.** 


The Strike Hard Campaign in Xinjiang has 
created arguably the world’s largest open air 
digital prison—and provided an early glimpse 
of what digital authoritarianism might have in 
store. 


The Strike Hard Campaign in Xinjiang has created 
arguably the world’s largest open air digital 
prison**—and provided an early glimpse of what 
digital authoritarianism might have in store.*® Yet 
what is so troubling about Xinjiang is not just the 
tech-driven mass detentions and human rights 
violations. It’s the prospect that Beijing will sell 
the technologies it has pioneered there to illiberal 
regimes abroad. 


Exporting Digital Authoritarianism 


China has_ sold’ information technology to 
foreign regimes for decades. From monitors and 
microprocessors to routers and radios, factories in 
Shenzhen and elsewhere have long manufactured 
communications technology used by states and 
security services abroad. 


Yet China’s export of information technology has 
changed recently in two ways. The first is that the 
products and services it sells are no longer low- 
cost knockoffs of high-tech products. Instead, 
Huawei, HikVision, Yitu, and others are now selling 
high-quality products that are not only produced 
in China but designed there too.*” Although some 
Chinese surveillance products are still reliant 
on Western semiconductors and sensors, many 
reflect genuine innovation and are as competitive 
on quality as they are on cost. Second, Beijing no 
longer views information technology solely in terms 
of economic development, but also its value to 
Chinese foreign policy and strategy.*® The Xi regime 


DEMOCRACY & DISORDER 
EXPORTING DIGITAL AUTHORITARIANISM: THE RUSSIAN AND CHINESE MODELS 


has aggressively pushed Chinese information 
technology as part of its Belt and Road Initiative 
(BRI), the strategic investment vehicle China uses 
to finance major infrastructure projects abroad.*° 
For Beijing, exporting its information technology 
is not only about securing important new sources 
of revenue and data, but also generating greater 
strategic leverage vis-a-vis the West.°° 


Beijing’s efforts have already begun to pay dividends. 
In Southeast Asia, Malaysia has integrated Chinese 
facial-recognition technology into its armed services, 
while Singapore aims to deploy the technology across 
a network of street cameras, similar to Beijing’s 
embrace of SkyNet.°* In East Africa, Ethiopian security 
services relied on telecommunications equipment 
from ZTE to monitor and surveil opposition activists 
and journalists.°? In Southern Africa, both Zimbabwe 
and Angola have signed partnerships with Chinese 
companies to provide Al for their ruling regimes, all 
under the auspices of BRI.°* In Venezuela, the Maduro 
regime has contracted with ZTE to build a national 
ID card, payment system, and “fatherland database” 
that will track individuals’ transactions alongside 
personal information such as birthdays and social 
media accounts. Opposition activists and human 
rights dissidents fear that Maduro’s real aim is for 
ZTE to effectively implement China’s “social credit 
system” within Venezuela.“ Chinese surveillance 
systems, or a basic version of them, have also been 
implemented in Ecuador, where footage collected by 
the government’s 4,300 cameras is transmitted to 
the intelligence services.°° Meanwhile, in the Middle 
East, Dubai has already begun to deploy Chinese 
technology as part of its “Police without Policemen” 
program,°> an ambitious project to reduce crime, 
replacing policemen with video surveillance and 
facial recognition technology.°’ Ecuador shows 
how technology built for China’s political system is 
now being applied — and sometimes abused — by 
other governments. At least 18 countries currently 
use Chinese surveillance and monitoring systems, 
and at least 36 governments have held Chinese- 
led trainings and seminars on “new media” or 
“information management.”°8 


As Chinese surveillance technology improves in 
quality and declines in cost, the global demand 
for Beijing’s model of digital authoritarianism will 
likely only grow. With 5G networks on the horizon, 
illiberal and hybrid regimes throughout Asia, the 
Middle East, Africa, and Latin America will all 
build out the next generation of their domestic 
telecommunications and surveillance systems over 
the coming decade. If liberal democracies do not 
present a compelling and cost-effective alternative 
to the Chinese model of digital governance and 
infrastructure, the authoritarian toolkit that Beijing 
has long honed at home will increasingly spread 
abroad. 


THE RUSSIAN MODEL 


Compared to Beijing’s early investmentin developing 
content-blocking capabilities in the 1990s, Moscow 
was late to the game. As a result, as the internet 
penetrated Russian society, the digital domain 
remained, at least initially, relatively unencumbered 
and free. Unlike their Chinese neighbors, for 
example, Russians can access Facebook, Twitter, 
and Google — all of which are blocked in China. But 
Russia’s unbridled net freedom was short-lived: by 
1998, the government began to adapt Soviet era 
surveillance technology, known as the System of 
Operative-Search Measures (SORM), for the digital 
domain. To supplement technological surveillance, 
starting in the early 2000s, the Russian state 
began to implement a series of laws that de facto 
criminalize criticism of the government, legalize 
unfettered surveillance of citizens’ online activities, 
and increase state control of the Russian internet 
or Runet. 


Beginning in 2014, the government made legal 
and technical moves to establish a_ so-called 
Russian “sovereign internet” based on the Chinese 
model. Russian President Vladimir Putin signed 
the sovereign internet law in May 2019, allowing 
the government’s media regulator, Rozkomnadzor, 
to seize the Russian internet if Russia were cut 
off from the global web.®° If successful, which is 
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People shout slogans during a rally to protest against tightening state control over the internet in Moscow, Russia. March 10, 
2019. REUTERS/Shamil Zhumatov 


debatable, the Russian government would be able 
to isolate the Russian internet in whole or in parts 
from the global net. The law is set to come into 
effect on November 1, 2019, and there is growing 
concern that Russia’s efforts would accelerate 
the fracturing of the global internet, perhaps even 
surpassing China’s initiative.“ 


In the long run, the Russian model may prove 
to be more adaptable globally as emerging 
authoritarian regimes that cannot afford 
China’s high-tech model seek greater control 
over domestic populations and influence 
abroad. 


Still, Russian surveillance technology relies less on 
filtering information before it reaches citizens (as is 
the case in China) and more on a repressive legal 
regime coupled with tightening information control 
and intimidation of internet service providers 
(ISPs), telecom providers, private companies, and 


civil society groups.® It is an ad hoc model utilizing 
legal, technical, and administrative means that is 
well-Suited to diffusion across aspiring authoritarian 
regimes.° And across the world, there are far more 
countries that are similar to Russia in terms of 
capabilities, economic resources, and computing 
resources than China. For this reason, Russia’s 
model may be an appealing, relatively low-tech and 
low-cost alternative to the Chinese model, because 
it does not necessitate high-tech information 
filtration capabilities and can be implemented 
without a pre-existing government firewall.°* While 
Russian companies’ main market for export of 
surveillance technologies has been the Russian 
“near abroad” — namely, some former Soviet states 
— Russian surveillance tech has appeared in the 
global south as well.® In the long run, the Russian 
model may prove to be more adaptable globally as 
emerging authoritarian regimes that cannot afford 
China’s high-tech model seek greater control over 
domestic populations and influence abroad. 
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Ad-hoc Surveillance 


SORM, the Russian government’s surveillance 
system, was _ initially developed by the Soviet 
intelligence agency (KGB) to monitor phone calls. 
It expanded to the internet to monitor email traffic, 
web browsing activity, and other digital data under 
a new iteration known as SORM-2. By 2015, an 
updated version — SORM-3 — would encompass all 
telecommunications. Under Russian law (more on 
this below) ISPs and telecom providers are required 
to install SORM equipment providing the Russian 
Federal Security Services (FSB) access to all data 
shared online without companies’ knowledge or 
control of which data are being shared and with 
whom. SORM works by basically copying all data 
flows on internet and telecom networks — sending 
one copy to the government and the other to 
the intended destination.°° SORM is the FSB’s 
“packdoor” to Russia’s internet.®” 


Since Putin’s return to the presidency in 2012, an 
increasing number of Russian state agencies have 
also been granted access to SORM surveillance 
and content moderation under the guise of “public 
safety” or counter-terrorism and extremism. In 
addition to the FSB, Roskomnadzor (the Russian 
media regulator), the Prosecutor General’s Office, 
the Federal Service for Surveillance on Consumer 
Rights and Human Wellbeing (Rospotrebnadzor), 
and the Federal Drug Control Service were granted 
the ability to block content without court order in 
2013.° 


To extend the reach of the SORM-3 system, the 
Ministry of Communications plans to localize 99% 
of all internet data by 2020, which would require 
ISPs to store Russian citizens’ personal data on 
Russian territory.°£2 The Ministry also plans to 
require that more customer/client information 
be accessible to SORM in the next three years, 
including drafted text messages.’° But the Russian 
government faces _ significant implementation 
challenges to effective surveillance. Most notably, 
the cost of mass surveillance related to all aspects 


of electronic tracking is high for the Russian 
government to implement — ranging from 130 to 
10 trillion rubles (approximately 2 to 150 billion 
U.S. dollars per year).’* Due to these high costs, the 
Russian government has invested more in targeting 
technologies that boost SORM’s precision rather 
than an all-encompassing content-filtering system. ’? 


In addition to SORM, Russia began to institute 
a video surveillance system in 2015 known as 
“Safe City.” The system allows the automatic 
transfer of information, including facial/moving 
objects recognition, to government authorities.’? 
This information is available to any executive 
or presidential body. The budget for “Safe City” 
implementation from 2012 to 2019 was an 
estimated $2.8 billion to cover all cities hosting 
the 2018 World Cup.” The city of Moscow has 
approximately 170,000 cameras, at least 105,000 
of which have been outfitted with facial recognition 
technology developed by the Russian firm 
NTechLabs.’® 


Non-compliance by private companies has also 
been an obstacle for Moscow. The Russian 
government’s battle with the messaging app 
“Telegram” illustrates the limits of the authorities’ 
reach. Telegram, founded by Russian entrepreneur 
Pavel Durov, refused to allow government access 
to the platform’s encrypted data, as required 
by Russian law. In April 2018, the government 
blocked Telegram, which in turn used various 
workarounds, including routing data through 
Amazon’s and Google’s cloud service, to still keep 
the app active. The Russian internet regulator found 
itself in the awkward position of having to block 
at least 18 million IP addresses, unintentionally 
disrupting banking, transportation, news sites, and 
other services.” Across Russian cities, Russians 
demonstrated in support of the app and internet 
freedom.” Google and Amazon conceded to the 
Russian government’s demands to clamp down 
on “domain fronting,” the technique that Telegram 
used to get around government monitoring. Still, the 
government’s failure to block Telegram revealed the 
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limits of Moscow’s capabilities, the importance of a 
free internet to Russian citizens, and the breadth of 
internet penetration across the country. 


Al-powered Surveillance 


Looking to China, Russia is eager to integrate 
artificial intelligence technologies into its system 
of surveillance. Speaking to Russian students 
in September 2017, Putin squarely positioned 
Russia in the technological arms race for Al when 
he declared that “whoever becomes the leader 
in [artificial intelligence] will become the ruler of 
the world.”’® Russia spends approximately $12.5 
million a year on Al research’? with hopes to 
grow the domestic Russian market for Al to $400 
million by 2021.°®° In May 2019, the Russian Direct 
Investment Fund (RDIF) raised $2 billion from foreign 
investors to support domestic Al development.®* 
Even with this new influx of investments, Russia 
would remain far behind China, which plans to grow 
its Al industry to $150 billion by 2030.* Still, the 
Russian government is ramping up its efforts to 
grow the Al sector. The Ministry of Defense, state- 
owned companies, and, to a much smaller extent, 
public-private partnerships and foreign investment 
are leading these efforts. 


Following Putin’s 2017 speech, the Russian Ministry 
of Defense took the lead in mobilizing the Russian 
government’s approach, which includes building 
an Al-infrastructure for research and development, 
engaging the private and civilian sectors in 
government projects, and organizing major Al 
conferences in Russia.®° The Ministry organized the 
first conference on Al in March 2018* and a second 
in April 2019 geared towards business solutions and 
Al technology optimization.®° In January 2019, Putin 
issued an official decree instructing the government 
to produce a national security strategy on Al.8° The 
decree tasks Sberbank, the state-controlled bank, 
with developing proposals for the Al strategy to be 
finalized in June 2019.®’ In a speech®® on May 30, 
2019, Putin previewed the forthcoming strategy 
that would include greater investment in STEM 


education, public-private partnerships, training, 
and an effort to protect intellectual property rights.° 
The strategy is part of the Russian government’s 
larger “Digital Economy of the Russian Federation” 
program, which aims to implement Al technologies in 
other sectors such as e-governance and the judicial 
system.°° The use of Al-driven predictive analytics 
in the Russian criminal system, for example, 
would allow the government to identify “potential 
offenders” and calibrate sentencing based on the 
threat they present to the regime.** 


Legalizing Digital Authoritarianism 


In 2016, a new package of laws, the so-called 
Yarovaya amendments, required telecom providers, 
social media platforms, and messaging services 
to store user data for three years and allow the 
FSB access to users’ metadata and encrypted 
communications.°2 While there is little known 
information on how Russian intelligence agencies 
are using these data, their very collection is an 
opportunity for intimidation and harassment of 
private companies and civil society organizations. 


Civil society groups and independent media have 
been the primary targets of legalized surveillance, 
repression, and censorship. The Russian 
government began blocking virtual private networks 
(VPNs) that allow access to banned content in 
July 2017. That fall, President Putin signed into 
law legislation allowing the Russian government 
to designate media organizations that receive 
funding from abroad as “foreign agents.” The 
law also grants the Russian authorities an 
expansive mandate to block online content, 
including social media websites, whose activities 
are deemed “undesirable” or “extremist.”°% In 
January 2018, requirements went into effect 
preventing social media and communications 
platforms users from remaining anonymous. These 
have been difficult to enforce so far because of non- 
cooperation by private companies. Taken together, 
these measures and their subsequent countless 
amendments have set up a complex legal web of 
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repression. They have also granted the Russian 
government the power to block access to any 
distributed information appealing for public protest 
if it designates it extremist or undesirable. 


Creating a “Sovereign” Russian Internet 


The Russian government began efforts to develop 
an internal internet “kill switch” in 2012, following 
anti-government protests over election fraud. The 
capability would go beyond blocking content or 
identifying potential dissenters — the aim is for 
the authorities to be able to switch off the country 
or specific regions from the global web while still 
maintaining the general operability of the internet.°° 
In February 2019, legislation to establish the so- 
called “sovereign Russian internet” passed the first 
reading in the Russian parliament (the Duma) with 
75% of the vote. President Putin signed it into law 
on May 1, 2019, and it is set to come into effect in 
November 2019. 


With this new measure, the government aims 
to establish control of Russian internet traffic 
by routing it through domestic exchanges. The 
law requires internet providers to install “free” 
equipment to automatically block banned websites, 
monitor (and prohibit by discretion) communication 
across borders,°° and allow Roskomnadzor to take 
centralized management at a “time of crisis.”°” 
In the long term, the bill has the potential to cut 
out small providers or control them, provide 
Roskomnadzor with a complete map of data 
exchange points, and restrict traditional bypass 
methods (VPNs, independent ISPs, etc.).9% It also 
takes aim at Telegram, which remains accessible in 
Russia primarily through VPN use. Implementation 
of the legislation will prove to be costly if not 
impossible given Russia’s high connectivity to the 
global web, which peaked in 2018, according to a 
Russian government index.°? Moscow will also have 
to create its own Domain Name System (DNS) and 
ISPs will need to install the required monitoring 
equipment at an estimated cost of $320 million 
dollars to the Russian government.*® The idea 


of a sovereign internet is also unpopular among 
Russians — only 23% support a sovereign internet 
model, while 52% believe that the internet in 
Russia should continue to develop in connection to 
the world.** Ultimately, the law may lead to greater 
segmentation of the World Wide Web — already 
segmented by China’s sovereignty principles — as 
Russia restricts its citizens’ access to global data. 


Exporting the Russian Model 


Countries in Russia’s near abroad are importing 
SORM technologies and replicating the Russian legal 
framework supporting population surveillance. In 
Kazakhstan, a replica of SORM allows for the latest 
deep packet inspection (DPI), in line with Russian 
standards. In 2018, the Kazakh National Security 
Committee implemented new technical regulations 
for its SORM system to grant the government real- 
time access to operators’ networks.*°? Belarus 
has had a SORM-style system since 2010.10° 
Kyrgyzstan’s surveillance network is also modeled 
on SORM and has matched Russian interception 
systems since 2012.1” With the exception of the 
Baltic States, Armenia, and Georgia, all other 
former Soviet republics have instituted aspects of 
the Russian digital authoritarian model at various 
times in their post-Cold War histories.t°° Two 
Russian companies, Protei and Peter-Service, have 
become main SORM providers since the early- 
2010s. Some of Protei’s customers are telecom 
companies in the Middle East (Bahrain, lraq, Qatar, 
etc.) and Latin America (Cuba, Mexico, Venezuela). 
Peter-Service has customers in Belarus, Abkhazia, 
Georgia, and Ukraine.*% 


Beyond limited technology exports, the Russian 
state has invested significant resources in 
information manipulation — initially tested on 
domestic audiences and then deployed against 
other countries. In this space, Russian activities 
are not limited to its near abroad but take aim 
against Western democracies. Through overt state- 
sponsored media outlets, such as RT and Sputnik, 
and covert information operations in the digital 
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domain, Moscow seeks to influence the information 
environment on a global scale. Whereas China’s 
efforts focus on promoting a positive view of China 
(or repressing negative views through various 
influence and intimidation techniques), the Russian 
approach aims to destabilize politics and polarize 
societies to weaken them from within. This zero- 
sum view of international relations has become 
part and parcel of Russian foreign policy. 


CONCLUSIONS AND RECOMMENDATIONS 


Responding to Digital Authoritarianism 


As Russia, China, and other states advance 
influence through forms of digital authoritarianism, 
stronger responses are needed from the U.S. and 
like-minded partners to limit the detrimental effects 
of their efforts. An initial step involves designating 
regimes as digital authoritarians if they routinely 
and purposefully employ mass surveillance without 
adequate safeguards and protections. Firms that 
supply digital authoritarian regimes should be 
sanctioned heavily—not just those in Russia and the 
United States, but also companies based in Europe, 
Israel, and elsewhere. Concurrently, controls should 
be tightened over exports of sensitive technologies 
to China and other digital authoritarians. 


Ultimately, the West will need to develop a 
democratic model of digital governance that can 
outcompete authoritarian ones. To do this, the 
technology sector and policymaking community 
in the United States and Europe will need to offer 
compelling models of digital surveillance that 
enhance security while still protecting civil liberties 
and human rights. 


To advance this goal, a digital governance code 
of conduct is needed. A coalition of democratic 
governments, tech companies, and civil society 
should develop such a code, which would include an 
articulation of operating procedures for addressing 
social media manipulation, common terms of use 
across platforms, and shared rules on personal 
data use. Finally, greater public awareness of this 


challenge is needed. To build resilience against 
foreign influence operations in democratic societies, 
governments should invest in raising public 
awareness around information manipulation. This 
should include funding educational programs that 
build digital critical thinking skills among youth. 


e Export controls. Although China can match 
the U.S. in software quality, it has yet to 
master semiconductor manufacturing. 
Some of the equipment that China relies on 
for mass surveillance systems incorporate 
advanced processors and sensors that are 
only produced in the west. The U.S. and 
Europe have already begun restricting the 
export of such technologies to China and 
should consider expanding the use of export 
controls. 


e Targeted sanctions. The United States should 
designate regimes as “digital authoritarian” if 
they routinely and purposefully employ mass 
surveillance without adequate safeguards 
and protections. Firms that supply digital 
authoritarian regimes should be sanctioned 
heavily—not just those in Russia and the 
U.S., but also companies based in the United 
States and Europe. 


e Democratic models. Where the export 
of digital authoritarianism is concerned, 
sanctions alone won’t be enough to 
check its spread. Ultimately, the West will 
need to develop a democratic model of 
digital governance that can outcompete 
authoritarian ones. To do this, the technology 
sector and policymaking community in the 
United States and Europe will need to offer 
compelling models of digital surveillance that 
enhance security while still protecting civil 
liberties and human rights. 


e Digital governance code of conduct. The 
U.S. and Europe should work to develop 
common practices, rules, and systems of 
digital governance. A coalition of democratic 
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governments, tech companies, and civil 
society should develop a code of conduct 
which should include an articulation of 
operating procedures for addressing social 
media manipulation, common terms of 
use across platforms, and shared rules on 
personal data use. 


e Public awareness. To build resilience against 


foreign influence operations in democratic 
societies, governments should invest in 
raising public awareness around information 
manipulation. This should include funding 
of educational programs that build digital 
critical thinking skills among youth. 
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